Encryption Key Policy Control Circuit for SOC Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

SOCs face vulnerabilities due to the transfer of encryption keywords, which can be exploited by hackers, especially when the SOC cannot control the usage or duration of the keyword.

Innovation Solution

Implementing a security circuit with a processor and interface controller to generate and manage keywords, including policies for usage, such as indicating allowed functional units, keyword size, encryption/decryption permissions, and time limits, thereby controlling the keyword's usage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If encryption keywords are transferred between SOC and external components, then data security is improved, but vulnerability to attacks increases due to unauthorized usage

Engineering Contradiction:
Improvedata securityVSAvoidvulnerability to attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by establishing usage policies and time limits for encryption keywords before they are transferred to external components. The system pre-configures constraints on keyword usage, including which functional units can use the keyword, for how long, and under what conditions, thereby preventing unauthorized usage before it can occur.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary mechanism in the form of a policy control system that mediates between the SOC and external components. This intermediary enforces usage policies on encryption keywords, controlling which components can access the keywords and for how long, thereby reducing direct vulnerability while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If keyword transfer is enabled for data encryption, then secure data sharing is improved, but control over keyword usage is lost

Engineering Contradiction:
Improvesecure data sharingVSAvoidcontrol over keyword usage
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent applies dynamics by implementing time-varying usage policies for encryption keywords. The system dynamically controls keyword accessibility based on time limits, allowing the keyword to be used only during specific time windows. This enables secure data sharing while maintaining operational control through temporal constraints.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the parameter of keyword accessibility by introducing time as a controlling variable. The usage policies modify the effective lifespan and accessibility parameters of encryption keywords, allowing the system to enable/disable keyword usage at different times, thereby balancing data sharing needs with control requirements.

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If unlimited keyword usage is permitted, then operational flexibility is improved, but security risk increases due to potential misuse

Engineering Contradiction:
Improveoperational flexibilityVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies periodic action by implementing time-limited usage policies that reset or expire at predetermined intervals. Encryption keywords are valid only for specific time periods, after which they must be renewed or replaced. This provides operational flexibility within defined periods while reducing long-term security risks through periodic key lifecycle management.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS12321443B2Authentication and control of encryption keys
Publication Date: 2025.06.03 APPLE INC
  • US12321443B2 patent drawing
  • US12321443B2 patent drawing
  • US12321443B2 patent drawing

AI summary

An apparatus, a method, and a system are presented in which the apparatus includes an interface control circuit that may be configured to receive a message including a cryptographic keyword and a policy value. The policy value may include one or more data bits indicative of one or more policies that define allowable usage of the cryptographic keyword. The apparatus also includes a security circuit that may be configured to extract the cryptographic keyword and the policy value from the message, and to apply at least one policy of the one or more policies to usage of the cryptographic keyword in response to a determination that an authentication of the message succeeded.